Aethris

Privacy Policy

Version applicable to the test phase (MVP)

Last updated: 20 July 2026

1. Introduction

This privacy policy describes how Aethris (“the Service”, “we”) collects, uses, retains and protects the personal data of persons who create an account or use the platform (“you”, “the user”).

Aethris is a narrative-writing platform for authors who wish to organise, write and manage their writing projects (character management, timeline, mind map of the relationships between characters, dedicated text editor). The MVP allows the creation of stories in text form only, in the following categories: novel, fanfiction, poetry, short story, screenplay and essay. Other formats (in particular manga and visual novel) are potential future developments of the Service but are not available at this stage.

This policy applies from the public test phase (MVP) onwards. During this phase, access to the features is free and complete; benefits may be granted at the full launch of the Service to all or some of the users who registered during this period, in accordance with the terms described in the Terms of Use.

2. Data controller

The controller of the personal data collected via Aethris is:

FieldInformation
NameNicolas Thys — publisher of the Service, operated on a personal basis (natural person)
AddressPostal address provided on request, via the email address below
Contact email (data protection)contact@aethris.art
Company number (CBE)Not applicable at this stage

Evolving legal status: as at the date of writing, the publisher of the Service operates as a natural person, as part of a student project with no direct commercial transaction within the application (see section 9 on funding). The Service is not intended to retain this status permanently: should the activity later be structured (for example under self-employed status on a secondary basis, or in a company form), this policy will be updated to reflect the identity of the new data controller, without this affecting the continuity of the user rights described herein.

3. Personal data collected

The table below summarises the categories of data processed by Aethris, their origin and their purpose.

3.1 Account data

DataPurposeLegal basis
Username + discriminator (4 digits)Unique identification of the accountPerformance of the contract (Art. 6(1)(b) GDPR)
Email addressAuthentication, service communications, password resetPerformance of the contract
Password (hashed — never stored in plain text)Secure authenticationPerformance of the contract
Preferred languageInterface displayPerformance of the contract
Avatar and bio (optional)Profile personalisationConsent / performance of the contract
Date of acceptance of the ToUProof of contractual consentLegal obligation / legitimate interest
Newsletter consent (opt-in) and consent timestampSending news and information about Aethris, upon voluntary sign-up separate from acceptance of the ToUConsent (Art. 6(1)(a) GDPR)
Supporter status and date grantedGranting access to content reserved for people supporting the project (dedicated visual themes)Performance of the contract / legitimate interest
History of support contributions (type and date)Keeping a record of the support received in order to determine the associated access rightsLegitimate interest
Storage volume used and register of uploaded files (path, folder, date)Enforcing the storage quota, linking each file to its owner, reliably deleting files that are no longer neededPerformance of the contract / legitimate interest

Supporter status is granted manually by the publisher, on the basis of a reconciliation with the account's email address. No banking or payment data is transmitted to Aethris or retained by the Service (see sections 3.6 and 9).

3.2 User-generated content

The narrative projects (novels, fanfiction, poetry, short stories, screenplays, essays), including the titles, synopses, chapters, textual content of sections, characters, relationships, timeline events, notes and inserted images, are data provided directly by the user in the course of using the Service.

  • This content is stored to enable its editing, backup and viewing by the user themselves.
  • It is accessible only to the account holder, except where a sharing feature is explicitly activated by the user (to date, no public sharing feature is available in the MVP).
  • Images inserted in the editor or used as covers are converted to and stored in WebP format on the Service's infrastructure.

3.3 Technical and security data

DataPurposeRetention period
IP address (per login session)Security, detection of fraudulent use of a refresh token30 days after expiry or revocation of the session
Browser user-agentDisplay of active sessions, security30 days after expiry or revocation of the session
Refresh tokensKeeping the user logged in without re-entering the password30 days, with rotation on each use
Timestamp of last use of a sessionAllowing the user to view and revoke their active sessions30 days
Email verification token (hashed, never stored in plain text)Confirming the email address at registrationSingle use; deleted after consumption or replacement
Password reset token (hashed, never stored in plain text)Enabling secure password resetSingle use; expires after 1 hour

An automated purge script deletes sessions that have been revoked or expired for more than 30 days (data minimisation, Art. 5(1)(e) GDPR). This mechanism runs as a scheduled task (cron) on the production infrastructure.

3.4 Technical cookies and local storage

The Service uses no advertising, audience-measurement or profiling cookies. Only the following mechanisms, strictly necessary for its operation, are used:

MechanismPurposeDuration
Session cookie (refresh token)Keeping you signed in without re-entering your password on every visit30 days, rotated on each use
Language preference cookieRemembering the display language you selected for the siteDuration set by the browser
Browser local storage (`localStorage`)Retaining certain display preferences (visual theme, editor settings) and avoiding reloading them on every pageUntil cleared by the user or until sign-out

These mechanisms fall within the exemptions from consent provided for trackers strictly necessary to deliver a service expressly requested by the user. Data held in the browser's local storage remains on your device and is not used for analytics or tracking purposes.

3.5 Writing statistics

In order to offer progress tracking (a system of “fragments” and “flames”), the Service records the number of words written per day, a personal goal, and cumulative counters. This data is linked to the user account and is used only for display to the user themselves; it is not sold or exploited for commercial or advertising purposes.

3.6 Data we do not collect

  • No advertising cookies or trackers, and no audience-measurement cookies (see section 3.4).
  • No audience-analytics tool (Google Analytics or equivalent) is deployed at this stage.
  • No payment data is processed by Aethris: the Service offers no paid features during the test phase (see section 9).
  • No sensitive data within the meaning of Art. 9 GDPR (origin, health, opinions, orientation, etc.) is intentionally collected; we ask users not to include such real information about themselves in the profile fields.

3.7 Data relating to minors

Use of Aethris is reserved for persons aged 16 or over, in accordance with the Terms of Use. The Service is not intended for persons below this age and does not knowingly collect their personal data. If we learn that an account has been created by a person who does not meet the required age, the associated data will be deleted. A parent or guardian who becomes aware that a minor in their care has provided personal data may contact us at contact@aethris.art to request its deletion.

4. Purposes of processing

Personal data is processed for the following purposes, and for these only:

  • Provide access to the Service and enable the creation, editing and backup of narrative projects;
  • Authenticate the user and secure their account (session management, anomaly detection);
  • Send the communications strictly necessary for the operation of the Service (registration confirmation, password reset, account-related notifications);
  • Provide technical support at the user's request;
  • Comply with applicable legal obligations, in particular regarding the retention of proof of consent and responding to requests to exercise rights;
  • Inform users registered during the test phase of developments in the Service and of the benefits associated with their early participation.
  • Send a newsletter to users who have explicitly consented to it, such consent being collected separately from acceptance of the ToU and never required to create an account; changeable at any time from the account settings.

No data is used for advertising profiling, resale to third parties, or automated decision-making producing legal effects on the user.

5. Legal bases for processing

Legal basis (Art. 6 GDPR)Processing concerned
Performance of the contract (6(1)(b))Account creation, operation of the editor, backup of projects, authentication
Consent (6(1)(a))Optional profile fields (avatar, bio); non-essential communications if introduced in the future
Legitimate interest (6(1)(f))Account security, session logging, fraud prevention
Legal obligation (6(1)(c))Retention of certain proofs (consent to the ToU), responding to the competent authorities where required by law

6. Data recipients and processors

Your data is never sold. It may be transmitted to the following technical providers, acting as processors within the meaning of Art. 28 GDPR, strictly to the extent necessary for the operation of the Service:

ProviderRoleData locationTransfer outside the EU
Hetzner Online GmbHHosting of the infrastructure (servers, database, uploaded files)Germany / European UnionNo
Brevo (Sendinblue SAS)Sending of transactional emails (account confirmation, password reset, notifications)France / European UnionNo

As at the date of writing this policy, none of these providers involves a transfer of personal data outside the European Union. If a future provider involving a transfer outside the EU were to be integrated (for example an additional hosting service), this policy would be updated to describe the appropriate safeguards put in place (the European Commission's standard contractual clauses, or an applicable adequacy decision).

Presentation video (YouTube): the Service's home page may feature a presentation video hosted on YouTube. This video is not loaded automatically: only a preview image, served from our own infrastructure, is displayed until you click. No request is sent to Google before that action on your part, and no cookie is placed. If you choose to start playback, the player is then loaded from the `youtube-nocookie.com` domain, designed to limit the placing of trackers; your IP address is at that point transmitted to Google LLC, an independent controller, under its own privacy policy. Simply not clicking on the video is enough to prevent any transmission.

Link to Tipeee: the Service's presentation page may redirect visitors wishing to support the project to an external Tipeee page. This link constitutes a redirection to an independent third-party service; Aethris transmits no personal data to Tipeee in this context, and any data processed by Tipeee (in the case of voluntary financial support) is governed by Tipeee's own privacy policy, which we invite you to consult before making any donation.

6.1 No transfer for commercial purposes

Aethris does not sell, rent or share any personal data with advertisers, data brokers, or third parties for marketing purposes. No advertising is displayed on the Service.

7. Retention periods

Data categoryRetention period
Account data (as long as the account is active)Lifetime of the account
Narrative content (projects, chapters, characters...)Lifetime of the account
Account after a deletion request30 days (reflection period / cancellation possible), then permanent and irreversible deletion
Login sessions (refresh tokens, IP, user-agent)30 days after expiry or revocation
Technical security logs12 months maximum, for security and anomaly-detection purposes
Technical backups (restoration after an incident)Limited period, defined by the backup rotation cycle

Account deletion triggers an already-implemented mechanism: a scheduled script permanently deletes, after a 30-day period following the request, the account together with all associated files (avatar, project cover images, characters, series, images inserted in the texts). Deletion of the user row then results, by cascade in the database, in the erasure of all projects, sections, characters, scenes, relationships, mind maps, timelines and sessions linked to that account. This mechanism implements the right to erasure provided for in Art. 17 GDPR. An error affecting a given account does not interrupt the processing of the other accounts awaiting deletion.

A residual copy of the deleted data may temporarily remain in the technical backups, until their automatic elimination at the end of the backup rotation cycle. During this interval, this data is no longer used and is retained solely for restoration purposes in the event of an incident.

8. Your rights

In accordance with the GDPR, you have the following rights over your personal data:

  • Right of access — obtain a copy of the data concerning you. A feature to export your data in JSON format, including the full content of your projects, is available directly from your account (limited to 3 exports per hour for security reasons);
  • Right to rectification — correct any inaccurate data concerning you. Most of your data can be changed directly from your account settings; certain information that cannot yet be changed independently, such as the email address, can be corrected on simple request to contact@aethris.art;
  • Right to erasure (“right to be forgotten”) — request the deletion of your account. This request triggers a 30-day period during which you can cancel the deletion, before permanent and irreversible erasure;
  • Right to restriction of processing — request the temporary suspension of certain processing in the cases provided for by law;
  • Right to portability — receive your data in a structured, commonly used format (JSON), via the export feature mentioned above;
  • Right to object — object to processing based on legitimate interest, on grounds relating to your particular situation;
  • Right to withdraw your consent at any time, where the processing is based on it, without affecting the lawfulness of processing carried out before that withdrawal.

To exercise any of these rights, you may contact us at contact@aethris.art, or use the dedicated features available in your account settings (data export, account deletion, management of active sessions).

You also have the right to lodge a complaint with the competent supervisory authority:

AuthorityContact details
Data Protection Authority (DPA) — BelgiumRue de la Presse 35, 1000 Brussels — www.autoriteprotectiondonnees.be

9. Funding and changes to the business model

During the test phase (MVP), access to Aethris is entirely free and all features are available without restriction. No financial transaction is processed by the Service itself.

A presentation page may offer a link to an external Tipeee page, allowing any interested person to financially support the development of the project, on a voluntary basis. This donation confers no particular contractual right and does not constitute a purchase of a service via Aethris.

The Service plans, for a later phase, the introduction of a freemium model including paid visual themes and an internal virtual currency. Should this occur, this privacy policy will be updated before the activation of these features in order to describe precisely the payment data processed, the payment provider(s) used, and the associated safeguards. Users will be informed of any substantial change in accordance with section 11.

Specific benefits may be granted at the full launch of the Service to all or some of the users who created an account during the test phase, their allocation being capable of being limited in particular to a set number of accounts. The precise terms of these benefits, together with the applicable allocation criteria and limits, will be communicated in due course and require the collection of no additional data at this stage.

10. Security measures

Aethris implements reasonable technical and organisational measures to protect your data, in particular:

  • Hashing of passwords (never stored in plain text);
  • Authentication via a short-lived access token (15 minutes) combined with a rotating refresh token, limiting the impact of any token theft;
  • Detection of abnormal reuse of a refresh token;
  • User visibility and revocation of their active sessions, with display of the associated IP address and browser;
  • Hosting within the European Union, on infrastructure subject to the GDPR;
  • Restriction of access permissions to uploaded files (validation of type, size, and destination folder);
  • Automated and regular purging of session data that has become unnecessary;
  • Implementation of encrypted backups of the data, intended to enable its restoration in the event of a technical incident. These backups are retained for a limited period of 30 days; data from a deleted account is permanently eliminated from them at the end of this rotation cycle.

As no system is infallible, we recommend that you use a unique and sufficiently strong password for your Aethris account, and never reuse that password on other services.

11. Changes to this policy

This policy may be updated to reflect changes in the Service, its legal status, or the applicable regulations. Any substantial change (in particular the introduction of payment-data processing, of new processors involving a transfer outside the EU, or of new purposes) will be subject to prior notice to users, by notification in the application or by email, before it takes effect.

The date of last update appears on the first page of this document.

12. Contact

For any question relating to this privacy policy or to the exercise of your rights, you may contact us at:

contact@aethris.art

We undertake to respond to any request within a reasonable time, and at the latest within the one-month period provided for by the GDPR (which may be extended by a further two months for complex requests, with prior notice to the requester).

Privacy Policy — Aethris